EUVD Vulnerability Catalog

EUVD-2026-94395

Severity: MEDIUM Base Score: 6.3 CVSS Version: 4.0

Vulnerability Description

MISP contains a race condition in the email-based one-time password (OTP) login flow. When two HTTP requests carrying the same valid OTP are submitted concurrently, both can successfully authenticate and establish a session. The root cause is that the OTP value is read from the shared store, validated, and then deleted in separate non-atomic steps, allowing a second in-flight request to read the same value before the first request's deletion takes effect. Preconditions: - The target MISP instance has email OTP login enabled. - The attacker possesses a valid, unexpired OTP (e.g., via email interception or social engineering). - The attacker can issue two HTTP POST requests in close temporal proximity. Impact: - The one-time-use guarantee of the OTP is violated; a single code can yield two authenticated sessions. - This weakens the authentication control and may facilitate unauthorized access if the OTP is shared or intercepted. Affected versions: <2.5.48

CVSS Vector Analysis

Below is the complete, human-readable breakdown of the CVSS metric string: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N

▪ Attack Vector (AV): Network
▪ Attack Complexity (AC): High
▪ Attack Requirements (AT): None
▪ Privileges Required (PR): None
▪ User Interaction (UI): None
▪ Vulnerability Confidentiality Impact (VC): None
▪ Vulnerability Integrity Impact (VI): Low
▪ Vulnerability Availability Impact (VA): None
▪ Subsequent Confidentiality Impact (SC): None
▪ Subsequent Integrity Impact (SI): Low
▪ Subsequent Availability Impact (SA): None

Affected Vendors & Systems

Vendor MISP

References & Advisory Links

Metadata Profile

Database Authority

European Union Agency for Cybersecurity (ENISA) EUVD

Assigner

CIRCL

EPSS Probability

0

Known Aliases
CVE-2026-107276 GHSA-fjjq-85mx-vg3v
Published On

2026-10-07

Last Updated

2026-10-07